Update the WordPress Ninja Forms plugin to the latest available version (at least 3.6.10).
Muhammad Adel discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Ninja Forms Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 3.6.10.
Authenticated PHP Objection Injection vulnerability
05.09.2022
Unauthenticated PHP Object Injection vulnerability
15.06.2022
Authenticated Stored CrossSite Scripting (XSS) vulnerability
13.06.2022
Authenticated Stored CrossSite Scripting (XSS) vulnerability
07.06.2022
Unauthenticated Email Address Disclosure vulnerability
22.03.2022